Blogger Widgets
Showing posts with label Browser. Show all posts
Showing posts with label Browser. Show all posts

Friday, 18 October 2013

Mozilla Firefox Add-ons A Hacker Must Have And Use #Hacker #Infosec #Browser




Firefox's one of the most secure browser in the world,like other browsers Mozilla Firefox has add-ons. This article brings the best and the most effective hacking add-ons ever on Firefox. In short this article's listing the most popular and interesting firefox add-ons that are useful for hackers and also security experts.The list vary from information gathering firefox add-ons to attacking tools/add-ons.
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
 All the add-on listed on this article are available and free on the Mozilla add-on website.


brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
brings you the best and most effective Hacking add-ons ever on Firefox. In short, we are listing a most popular and interesting Firefox add-ons that are useful for Hackers. This list of 11 add-ons vary from information gathering tools to attacking tools. All these add-ons are available for free and you can download from the Mozilla add-on website. So friends lets see what Darkhtu has bring this time for you. I will list them in way from top( I like most) to bottom pattern but note that all of them are extremely good tools. - See more at: http://www.darkhtu.net/2013/10/11-firefox-addons-hacker-must-have-and.html#sthash.DmID8xii.dpuf
1. Tamper Data
   

Tamper data is an great tool to to view and modify HTTP/HTTPS headers and post parameters. We can alter each request going from our machine to destination host with this. Thus it helps in security testing web application by modifying POST parameters. It can be used in performing XSS and SQL Injection attacks by modifying header data. Add Tamper data to Firefox: https://addons.mozilla.org/en-us/firefox/addon/tamper-data/
 

2. Firebug
   

Firebug is a nice add-on that integrates a web development tool inside the browser. With this tool, you can edit and debug HTML, CSS and JavaScript live in any webpage to see the effect of changes. It helps in analyzing JS files to find XSS vulnerabilities. It’s an really helpful add-on in finding DOM based XSS for security testing professionals. Add firebug to your browser : https://addons.mozilla.org/en-US/firefox/addon/firebug/
 
 

3. Hackbar  

Hackbar is a simple penetration tool for Firefox. It helps in testing simple SQL injection and XSS holes. You cannot execute standard exploits but you can easily use it to test whether vulnerability exists or not. You can also manually submit form data with GET or POST requests. It also has encryption and encoding tools. Most of the times, this tool helps in testing XSS vulnerability with encoded XSS payloads. It also supports keyboard shortcuts to perform various tasks.I am sure, most of the persons in the security field already know about this tool. This tool is mostly used in finding POST XSS vulnerabilities because it can send POST data manually to any page you like. With the ability of manually sending POST form data, you can easily bypass client side validations of the page. If your payload is being encoded at client side, you can use an encoding tool to encode your payload and then perform the attack. If the application is vulnerable to the XSS, I am sure you will find the vulnerability with the help of the Hackbar add-on on Firefox browser. Add Hackbar to Firefox: https://addons.mozilla.org/en-US/firefox/addon/hackbar/
 




 4. Cookies Manager +  
Cookie Manager is one of the greatest tool ever made. Using this tool you can actually play with cookies. You can alter almost all cookie using this tool. You can use Cookies manager to view, edit and create new cookies. It also shows extra information about cookies, allows edit multiple cookies at once and backup/restore them. Add Cookies Manager to Firefox: https://addons.mozilla.org/en-US/firefox/addon/cookies-manager-plus/
 
5. NoScript  

No Script add-ons greatness is beyond imagination. With this tool you can monitor each an every script running on website, you can block any of scripts and see what actually that scripts does on website. But this add-on is for experts, newbies will face problems using this. Note: If you are testing XSS, HTTPS header modifications, Injection attacks on any website you need to disable this plugin because it will not allow you to do so.  Add NoScript to Firefox: https://addons.mozilla.org/en-us/firefox/addon/noscript/
 
6. Grease Monkey  

Grease Monkey is an counter part of No Script, its actually behaves opposite of Noscript. We use Noscript to block the scripts and use GreaseMonkey to run the scripts. It allows you to customize the way a web page displays or behaves, by using small bits of JavaScript.  Add Grease Monkey to Firefox : https://addons.mozilla.org/en-US/firefox/addon/greasemonkey/
 


 7. User Agent Switcher

User Agent Switcher add-on; adds a one click user agent switch to the browser. It adds a menu and tool bar button in the browser. Whenever you want to switch the user agent, use the browser button. User Agent add on helps in spoofing the browser while performing some attack. Add user agent Switcher to Firefox: https://addons.mozilla.org/en-US/firefox/addon/user-agent-switcher/
 

8. CryptoFox  

CryptoFox is an encryption or decryption tool for Mozilla Firefox. It supports most of the available encryption algorithm. So, you can easily encrypt or decrypt data with supported encryption algorithm. This add-on comes with dictionary attack support, to crack MD5 cracking passwords. Although, it hasn’t have good reviews, it works satisfactorily. Add CryptoFox to Firefox: https://addons.mozilla.org/en-US/firefox/addon/cryptofox/
 

9. SQL Inject Me  

SQL Inject Me is another nice Firefox add-on used to find SQL injection vulnerabilities in web applications. This tool does not exploit the vulnerability but display that it exists. SQL injection is one of the most harmful web application vulnerabilities, it can allow attackers to view, modify, edit, add or delete records in a database.The tool sends escape strings through form fields, and tries to search database error messages. If it finds a database error message, it marks the page as vulnerable. Hackers can use this tool for SQL injection testing. Add SQL Inject Me to Firefox: https://addons.mozilla.org/en-us/firefox/addon/sql-inject-me/ 
 

10.  XSS ME  

Cross Site Scripting is the most found web application vulnerability. For detecting XSS vulnerabilities in web applications, this add-on can be a useful tool. XSS-Me is used to find reflected XSS vulnerabilities from a browser. It scans all forms of the page, and then performs an attack on the selected pages with pre-defined XSS payloads. After the scan is complete, it lists all the pages that renders a payload on the page, and may be vulnerable to XSS attack. Now, you can manually test the web page to find whether the vulnerability exists or not. Add XSS ME to Firefox: https://addons.mozilla.org/en-us/firefox/addon/xss-me/
 

11.  Passive Recon
 

Last but not the least. Passive recon is a good information gathering tool. 
PassiveRecon provides information security professionals with the ability to perform "packetless" discovery of target resources utilizing publicly available information. It gathers information like DnsStuff tool available on backtrack.
Add Passive Recon to Firefox: https://addons.mozilla.org/en-US/firefox/addon/passiverecon/



---------------------------- Source Of The Article -------------------------------




Tuesday, 10 September 2013

Mozilla Recovery - crack master passwords #Passwords #Mozilla #Firefox



About the program
Requirements: Java 7 or a higher version

Posted Image

Once you start the program, it searches automatically for default locations of your key3.db in Firefox and, if not found, in the Thunderbird application directory. I prepared and tested this for Windows 7 and Linux. If it is not working for your OS, please tell me the default location for it. I just need the information to put that in. You can change the location by hand, of course.

key3.db is the file that is used to recover the master password. You can start a wordlist attack on that. The program ships with a default worldlist, but it is small (I didn't want to upload a wordlist file that adds several megabytes to the program). You can use your own list by changing the location.

Alternatively you can start a bruteforce attack by activating the "bruteforce" checkbox. Although I used threads, this is limited to a word length of five (a bruteforce attack with a wordlength of six would take several days, so I don't allow that) and the alphabet a-zA-Z by now. I got about 30000 password tests per second on my machine.

Once you got the master password, it is very easy to obtain saved login information from signons.sqlite, since both, Thunderbird and Firefox, will show usernames and passwords in plain text. (google if you don't know how)

Conclusion: Always set a master password if you save login information with Thunderbird or Firefox. Otherwise the login information can be obtained without any problems.

 

About the source

The only (non-standard) library I used is apache.log4j for logging purposes. You will see a properties file and a log folder. The standard logging level is WARN. If you change this level to INFO or DEBUG, the master passwords found with the program will be saved in there, so be careful with that option.

Lines of code without comments and empty lines: 914
Lines of code with everything else: 1141

The source is attached as Source.zip.

The code was tested for: Firefox 9.01 Thunderbird 9.01, Windows 7, Arch Linux
If you have a different setting, you can help me by telling me that it worked or that it didn't.
Edit: According to Kulverstukas and Superfly it works in Windows XP too. theellemist tested it on Windows Vista. Thanks to you.

Problems?

Please make sure that you have Java 7 or a higher version
* Mozilla Recovery.zip (471.23 kB -)
* Source.zip (452.76 kB -)

How Mozilla Saves Passwords #Programming #Passwords



This paper is written from the view of a programmer. It describes which algorithms are used by Mozilla to encrypt login data, i.e. saved passwords and usernames for websites in Firefox or the login data of your e-mail accounts in Thunderbird. I will provide some example code (Java) from this Mozilla Recovery program.


An information that you will find without problems is the location of your login data: It is the signons.sqlite (or signons.txt, signons3.txt in older versions), which can be found in the profile folder of your application.

First thing I did was researching about the sqlite format: http://www.sqlite.org/fileformat2.html
It is recommended to use a hex editor to compare the description with your own signons.sqlite file.
The format is well documented, so writing a program that obtains data from an sqlite file shouldn't be a problem.

Because I read that the data is encoded in Base64 and not encrypted if no master password is set, I copied a username entry and tried to decode. But it didn't work. I guess it worked with older versions. Now there is some kind of encryption too.

I searched for open-source programs that recover passwords from Firefox or Thunderbird and found this: http://securityxploded.com/thunderbirdpassdecryptor.php
Old website entries told me it was open-source, but I couldn't find any source to download. Old postings in the forum of securityxploded told me, that they changed this. Some people had used their code for writing maleware, so antivirus scanner recognized their program as a virus. It is pretty sad that the lazyness (not writing their own code, just grieving) and improvidence of some people forced the authors of ThunderbirdPassDecryptor to hide their knowledge. The further search for open-source programs was not fruitful.

In fact, signons.sqlite is useless without the key3.db file, which also resides in the profile folder of your application. This is where the trouble began. I couldn't find information about that file for a long time, so I downloaded the source code of Thunderbird, looked into it for several days and learned more about it's inner workings. I discovered that the login data in the signons.sqlite file is encrypted with TripleDES in CBC mode. The key used for the encryption is saved in key3.db and encrypted as well.

One day I stumbled on this website and it helped me a lot: http://www.drh-consultancy.demon.co.uk/key3.html
It describes how the keys in key3.db can be obtained. But not everything is correct anymore. Some changes are necessary.


First thing that made me think:
Quote
Initially you will need the database password

Where do I get that from?
I just guessed that this is the master password and was right.

I also got the idea that the entry values should follow right after the entry name (I am not sure if it is standard knowledge to do it in another way). I.e. looking at the key3.db in a hex editor you might get that picture on the plain text side:

...................password-check.Version..........

Which means the password-check entry would only have a one byte value. That couldn't be true. But the version entry which follows right after, only has a one byte value. So I tried it backwards, with the entry name following it's value (which lead to the problem to find out where the entries start). It was still not enough to get it working.

Since this website provides some test vectors (I am very grateful for that), I was able to implement and verify the decryption algorithm. Now I knew that it worked with the data on this website, but it still didn't work with my own key3.db file.
I can't really say how I got the idea, but I changed the length of the global salt entry from 16 bytes to 20 bytes. I guess it was just out of a hunch while looking at the hex values. Surprisingly this was the right thing. My test output decrypted the string "password-check" and I was happy. This is how I got the main algorithm for checking if a master password is the right one.

I still didn't implement a program for obtaining the login data out of signons.sqlite, once you got the key entries from key3.db. But my hunger for knowing how it works is satisfied and implementing it shouldn't be necessary at all. Reason: Thunderbird and Firefox show you the data (passwords included) in plaintext, if you know the master password. If no master password is given, the data is not secured at all, just encrypted with a hardcoded key: http://www.infond.fr/2010/04/firefox-passwords-management-leaks.html
(I didn't verify this yet, but I will)

How Mozilla saves login data:

Summary: login data is saved in signons.sqlite. It is encoded in Base64, encrypted with TripleDES in CBC mode and standard block padding. The key for the decryption is saved in key3.db. The entries in key3.db are encrypted with the master password. The decryption algorithm (of the key3.db entries) is not straight forward, but shown right after.

Sqlite Format: http://www.sqlite.org/fileformat2.html

Netscape Communicator Key Database Format: http://www.drh-consultancy.demon.co.uk/key3.html

Work through this description, but change the following:
  • the global salt value is 20 bytes (not 16 bytes) long (I think there may be a value indicating the length of the global salt somewhere)
  • the plain text entry names (i.e. Version, global salt) follow after their values
  • the database password is the master password
To verify the master password and your decryption algorithm, use the check-password entry. Its value is the encrypted string "check-password".

Java example code: extracted from MozillaRecovery

Key3.db key derivation algorithm:

The comments are in the notation of the website mentioned above.
Code: Java
  1. private static String decrypt(byte[] password, byte[] es, byte[] gs, byte[] text) {
  2.         try {
  3.             // HP = SHA1(global-salt||password)
  4.             byte[] hp = SHA.sha1(appendArray(gs, password));
  5.             byte[] pes = Arrays.copyOf(es, 20);
  6.             // CHP = SHA1(HP||ES)
  7.             byte[] chp = SHA.sha1(appendArray(hp, es));
  8.             // k1 = CHMAC(PES||ES)
  9.             byte[] k1 = SHA.sha1Hmac(appendArray(pes, es), chp);
  10.             // tk = CHMAC(PES)
  11.             byte[] tk = SHA.sha1Hmac(pes, chp);
  12.             // k2 = CHMAC(tk||ES)
  13.             byte[] k2 = SHA.sha1Hmac(appendArray(tk, es), chp);
  14.             // k = k1||k2
  15.             byte[] k = appendArray(k1, k2);
  16.             byte[] desKey = Arrays.copyOf(k, 24);
  17.             byte[] desIV = Arrays.copyOfRange(k, k.length - 8, k.length);
  18.             return new TripleDES(desKey, desIV).decrypt(text);
  19.         } catch (NoSuchAlgorithmException e) {
  20.             logger.fatal(e.getMessage());
  21.             e.printStackTrace();
  22.         } catch (BadPaddingException e) {
  23.             logger.debug(e.getMessage() + ". Probably wrong key.");
  24.         }
  25.         return null;
  26.     }


SHA-1 and HMAC-SHA1:
Code: Java
  1. import java.security.InvalidKeyException;
  2. import java.security.MessageDigest;
  3. import java.security.NoSuchAlgorithmException;
  4.  
  5. import javax.crypto.Mac;
  6. import javax.crypto.spec.SecretKeySpec;
  7.  
  8. public class SHA {
  9.  
  10.     private static final String HMAC_SHA1_ALGORITHM = "HmacSHA1";
  11.     private static final String SHA1_ALGORITHM = "SHA-1";
  12.  
  13.     public static byte[] sha1Hmac(byte[] data, byte[] key) {
  14.         try {
  15.             SecretKeySpec signingKey = new SecretKeySpec(key,
  16.                     HMAC_SHA1_ALGORITHM);
  17.             Mac mac = Mac.getInstance(HMAC_SHA1_ALGORITHM);
  18.             mac.init(signingKey);
  19.             return mac.doFinal(data);
  20.         } catch (NoSuchAlgorithmException | InvalidKeyException e) {
  21.             e.printStackTrace();
  22.         }
  23.         return null;
  24.  
  25.     }
  26.    
  27.     public static byte[] sha1(byte[] text) throws NoSuchAlgorithmException {
  28.         MessageDigest md = MessageDigest.getInstance(SHA1_ALGORITHM);
  29.         md.update(text, 0, text.length);
  30.         return md.digest();
  31.     }
  32. }}


TripleDES:
Code: Java
  1. import java.io.UnsupportedEncodingException;
  2. import java.security.InvalidAlgorithmParameterException;
  3. import java.security.InvalidKeyException;
  4. import java.security.NoSuchAlgorithmException;
  5. import java.security.NoSuchProviderException;
  6. import java.security.spec.InvalidKeySpecException;
  7. import java.security.spec.KeySpec;
  8.  
  9. import javax.crypto.BadPaddingException;
  10. import javax.crypto.Cipher;
  11. import javax.crypto.IllegalBlockSizeException;
  12. import javax.crypto.NoSuchPaddingException;
  13. import javax.crypto.SecretKey;
  14. import javax.crypto.SecretKeyFactory;
  15. import javax.crypto.spec.DESedeKeySpec;
  16. import javax.crypto.spec.IvParameterSpec;
  17.  
  18. public class TripleDES {
  19.     private KeySpec keySpec;
  20.     private SecretKey key;
  21.     private IvParameterSpec iv;
  22.  
  23.     public TripleDES(byte[] keyBytes, byte[] ivString) {
  24.         try {
  25.             keySpec = new DESedeKeySpec(keyBytes);
  26.             key = SecretKeyFactory.getInstance("DESede")
  27.                     .generateSecret(keySpec);
  28.             iv = new IvParameterSpec(ivString);
  29.         } catch (InvalidKeySpecException | NoSuchAlgorithmException
  30.                 | InvalidKeyException e) {
  31.             e.printStackTrace();
  32.         }
  33.  
  34.     }
  35.  
  36.     public byte[] encrypt(byte[] text) {
  37.         if (text != null) {
  38.             try {
  39.                 Cipher cipher = Cipher.getInstance("DESede/CBC/PKCS5Padding",
  40.                         "SunJCE");
  41.                 cipher.init(Cipher.ENCRYPT_MODE, key, iv);
  42.                 return cipher.doFinal(text);
  43.             } catch (IllegalBlockSizeException | InvalidKeyException
  44.                     | InvalidAlgorithmParameterException
  45.                     | NoSuchAlgorithmException | NoSuchProviderException
  46.                     | NoSuchPaddingException | BadPaddingException e) {
  47.                 e.printStackTrace();
  48.             }
  49.         }
  50.  
  51.         return null;
  52.     }
  53.  
  54.     public String decrypt(byte[] text) throws BadPaddingException {
  55.         if (text != null) {
  56.             try {
  57.                 Cipher cipher = Cipher.getInstance("DESede/CBC/PKCS5Padding",
  58.                         "SunJCE");
  59.                 cipher.init(Cipher.DECRYPT_MODE, key, iv);
  60.                 byte[] result = cipher.doFinal(text);
  61.                 return new String(result, "UTF8");
  62.             } catch (NoSuchAlgorithmException | NoSuchProviderException
  63.                     | NoSuchPaddingException | IllegalBlockSizeException
  64.                     | InvalidKeyException | InvalidAlgorithmParameterException
  65.                     | UnsupportedEncodingException e) {
  66.                 e.printStackTrace();
  67.             }
  68.         }
  69.         return null;
  70.     }
  71. }